CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,915 vulnerabilities with CWE-89
CVE-2015-1616
McAfee DLPe <9.3.400 - SQL Injection
CVE-2015-1434
my little forum <2.3.4 - SQL Injection
CVE-2015-1471
Pragyan CMS 3.0 - SQL Injection via User Parameter
CVE-2015-0580
Cisco Secure Access Control System < 5.5.0.46 - Authenticated SQL Injection via ACS View Reporting Interface
CVE-2015-1576
u5CMS < 3.9.3 - SQL Injection via Multiple Parameters
CVE-2015-1518
redaxscript < 2.2.0 - SQL Injection via search_terms Parameter
CVE-2015-1514
FancyFon FAMOC <3.17.4 - SQL Injection
CVE-2015-1513
SIPhone Enterprise PBX - SQL Injection
CVE-2015-1467
Fork CMS < 3.8.6 - Authenticated SQL Injection via Translations Language or Type Parameter
CVE-2015-1442
ZeroCMS <= 1.3.3 - Authenticated SQL Injection via user_id Parameter
CVE-2015-1479
ZOHO ManageEngine SDP <9.0.9031 - SQL Injection
CVE-2015-1477
CMSJunkie J-ClassifiedsManager - SQL Injection
CVE-2015-1476
xlinkerz ecommerceMajor - SQL Injection
CVE-2015-1441
Piwigo <2.5.6, <2.6.5, <2.7.3 - SQL Injection
CVE-2015-1428
Sefrengo < 1.6.1 - SQL Injection via sefrengo Cookie or value_id Parameter
CVE-2015-1405
Content Rating Extbase <2.0.3 - SQL Injection
CVE-2015-1403
TYPO3 Content Rating <1.0.3 - SQL Injection
CVE-2015-1400
NPDS Revolution 13 - SQL Injection via Search Query Parameter
CVE-2015-1450
Restaurant Biller - SQL Injection via cid Parameter
CVE-2015-1393
Photo Gallery <1.2.11 - SQL Injection
CVE-2015-1423
Gecko CMS 2.2-2.3 - Authenticated SQL Injection via Admin Index Parameters
CVE-2015-1372
ferretCMS 1.0.4-alpha - SQL Injection
CVE-2015-1369
Sequelize <2.0.0-rc7 - SQL Injection
CVE-2015-1367
CatBot 0.4.2 - SQL Injection via lastcatbot Parameter
CVE-2015-1364
Free Reprintables ArticleFR <3.0.5 - SQL Injection
Details
Vulnerabilities
19,915
Exploit Likelihood
High